2024 CVE Vulnerabilities

39,250 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-22818HIGH8.8FlyCms v1.0 contains a Cross-Site Request Forgery (CSRF) vulnerbility via /system/site/filterKeyword_save
CVE-2024-22817HIGH8.8FlyCms v1.0 contains a Cross-Site Request Forgery (CSRF) vulnerability via /system/email/email_conf_updagte
CVE-2024-22603HIGH8.8FlyCms v1.0 contains a Cross-Site Request Forgery (CSRF) vulnerability via /system/links/add_link
CVE-2024-22601HIGH8.8FlyCms v1.0 contains a Cross-Site Request Forgery (CSRF) vulnerability via /system/score/scorerule_save
CVE-2024-22699HIGH8.8FlyCms v1.0 contains a Cross-Site Request Forgery (CSRF) vulnerability via /system/admin/update_group_save.
CVE-2024-0607MEDIUM6.6A flaw was found in the Netfilter subsystem in the Linux kernel. The issue is in the nft_byteorder_eval() function, wher...
CVE-2024-0409HIGH7.8A flaw was found in the X.Org server. The cursor code in both Xephyr and Xwayland uses the wrong type of private at crea...
CVE-2024-0408MEDIUM5.5A flaw was found in the X.Org server. The GLX PBuffer code does not call the XACE hook when creating the buffer, leaving...
CVE-2024-22593HIGH8.8FlyCms v1.0 contains a Cross-Site Request Forgery (CSRF) vulnerability via /system/admin/add_group_save
CVE-2024-22592HIGH8.8FlyCms v1.0 contains a Cross-Site Request Forgery (CSRF) vulnerability via /system/user/group_update
CVE-2024-22591HIGH8.8FlyCms v1.0 contains a Cross-Site Request Forgery (CSRF) vulnerability via /system/user/group_save.
CVE-2024-22568HIGH8.8FlyCms v1.0 contains a Cross-Site Request Forgery (CSRF) vulnerability via /system/score/del.
CVE-2024-22549MEDIUM5.4FlyCms 1.0 is vulnerable to Cross Site Scripting (XSS) in the email settings of the website settings section.
CVE-2024-22548MEDIUM5.4FlyCms 1.0 is vulnerable to Cross Site Scripting (XSS) in the system website settings website name section.
CVE-2024-22317CRITICAL9.1IBM App Connect Enterprise 11.0.0.1 through 11.0.0.24 and 12.0.1.0 through 12.0.11.0 could allow a remote attacker to ob...
CVE-2024-0669HIGH7.1A Cross-Frame Scripting vulnerability has been found on Plone CMS affecting verssion below 6.0.5. An attacker could stor...
CVE-2024-0580HIGH7.5Omission of user-controlled key authorization in the IDMSistemas platform, affecting the QSige product. This vulnerabili...
CVE-2024-0381MEDIUM5.4The WP Recipe Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the use of the 'tag' attribute...
CVE-2024-0655CRITICAL9.8A vulnerability has been found in Novel-Plus 4.3.0-RC1 and classified as critical. Affected by this vulnerability is an ...
CVE-2024-0654HIGH7.8A vulnerability, which was classified as problematic, was found in DeepFaceLab pretrained DF.wf.288res.384.92.72.22. Aff...
CVE-2024-0652MEDIUM4.8A vulnerability was found in PHPGurukul Company Visitor Management System 1.0. It has been rated as problematic. Affecte...
CVE-2024-0651HIGH7.2A vulnerability was found in PHPGurukul Company Visitor Management System 1.0. It has been declared as critical. Affecte...
CVE-2024-23525MEDIUM6.5The Spreadsheet::ParseXLSX package before 0.30 for Perl allows XXE attacks because it neglects to use the no_xxe option ...
CVE-2024-22416HIGH8.8pyLoad is a free and open-source Download Manager written in pure Python. The `pyload` API allows any API call to be mad...
CVE-2024-0650MEDIUM6.1A vulnerability was found in Project Worlds Visitor Management System 1.0. It has been classified as problematic. Affect...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now